CVE-2026-70573
massHeap Buffer Overflow in Windows Biometric Service Enables Local Privilege Escalation
CVE-2026-70573 is a heap-based buffer overflow (arising from improper input validation, CWE-20/CWE-122) in the Windows Biometric Service, the Windows component that handles Windows Hello and fingerprint/face authentication. It is triggered when the service processes crafted input from a local, already-authenticated user with low privileges. A successful exploit allows the attacker to elevate privileges on the local machine, gaining high-level (typically SYSTEM) access to the confidentiality, integrity, and availability of that host. Any Windows system running the Biometric Service is affected — most relevantly desktops and laptops with biometric hardware such as fingerprint readers or IR cameras. There is no known public proof-of-concept, it is not in CISA KEV, and EPSS puts 30-day exploitation probability at a low 0.3% (19th percentile), so no active exploitation is currently known.
What to do: Patch via the current Microsoft cumulative/security update; the data does not list specific fixed builds, so map CVE-2026-70573 against the affected versions in the official MSRC advisory before deploying. Prioritize fleet assets where Windows Hello or third-party biometric logons are enabled, and verify installation of the fix with your patch-management tooling. As interim risk reduction, limit creation of low-privilege local accounts on shared endpoints and monitor the advisory for any change in exploitation status.
| Microsoft Windows Biometric Service (Windows operating system component) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
- Vendors
- microsoft
- Products
- windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2016, windows server 2019, windows server 2022, windows server 2025
- Weakness
- CWE-20, CWE-122
- Vector
- CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.